Do not report security vulnerabilities through public GitHub issues.
Please use the Private Vulnerability Disclosure feature of GitHub.
Alternatively, you can also send them by email to [email protected]. You can encrypt your mail using GnuPG if you want.
See the security.txt from CrabNebula
Contact: mailto:[email protected]
Expires: 2026-06-05T06:30:00.000Z
Encryption: https://crabnebula.dev/.well-known/pgp.txt
Preferred-Languages: en,de,fr
Canonical: https://crabnebula.dev/.well-known/security.txt
Include as much of the following information:
- Type of issue (e.g. buffer overflow, privilege escalation, etc.)
 - The location of the affected source code (tag/branch/commit or direct URL)
 - Any special configuration required to reproduce the issue
 - The distribution affected or used for reproduction.
 - Step-by-step instructions to reproduce the issue
 - Impact of the issue, including how an attacker might exploit the issue
 - Preferred Languages
 
We prefer to receive reports in English. If necessary, we also understand French and German. Thank you.